Remote Code Execution Vulnerability in Oracle Retail Xstore Point of Service by Oracle
CVE-2017-10214

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

A vulnerability exists in the Oracle Retail Xstore Point of Service, which allows unauthenticated attackers with network access via HTTP to compromise the system. This flaw can lead to unauthorized access to critical sensitive data and allow attackers to perform unauthorized updates, inserts, or deletions of data within the Oracle Retail Xstore system. Supported versions affected include 6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x, and 16.0.0. The vulnerability poses significant risks to confidentiality and integrity of the information managed by the Oracle Retail Xstore Point of Service.

Affected Version(s)

Retail Xstore Point of Service 6.0.x

Retail Xstore Point of Service 6.5.x

Retail Xstore Point of Service 7.0.x

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.